<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecurityChef</title>
	<atom:link href="http://securitychef.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://securitychef.com</link>
	<description>Your daily diet of security goodness!</description>
	<lastBuildDate>Mon, 26 Sep 2011 02:23:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>Student ID necessary for Security?</title>
		<link>http://securitychef.com/2011/student-id-necessary-for-security/</link>
		<comments>http://securitychef.com/2011/student-id-necessary-for-security/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 02:22:31 +0000</pubDate>
		<dc:creator>alice</dc:creator>
				<category><![CDATA[Personal Protection]]></category>

		<guid isPermaLink="false">http://securitychef.com/?p=283</guid>
		<description><![CDATA[School ID Card Systems provide more than Student ID&#8217;s, they help schools create a secure learning environment. Educational institutions of all shapes and sizes rely on ID cards as a way to increase security while also delivering a great deal of convenient functionality. As security concerns grow and budgets tighten, it’s becoming more and more [...]]]></description>
			<content:encoded><![CDATA[<p>School ID Card Systems provide more than Student ID&#8217;s, they help schools create a secure learning environment. Educational institutions of all shapes and sizes rely on ID cards as a way to increase security while also delivering a great deal of convenient functionality. As security concerns grow and budgets tighten, it’s becoming more and more important for schools to maintain effective ID card programs. You can protect your students, faculty and facility and at the same time, streamline operations and procedures, while reducing costs.</p>
<p>A new student comes in, and while their paperwork is being filled out, an ID card is printed. This ID card has a full colour picture of the student, their signature, and a barcode or magnetic stripe.</p>
<p>The student can use it as a library card, it is scanned to record the checkout details. The ID card can also be used to log into a computer in class or the library. That computer then allows access to specific applications only, based on their pre-set configured access levels.</p>
<p>When visiting the cafeteria, instead of handing over money, they can simply have their ID card scanned. As it also works as a meal card, the total amount is deducted directly from their student account so there is no risk of monetary theft at the school.</p>
<p>If a student were to attempt to enter the staff lounge, they would be unable to because their special student ID card also works as a security card, and it does not allow them access to the staff lounge and other restricted areas.</p>
<p>When the student enters a classroom, they swipe their ID and are marked present. When they leave the classroom, they swipe again to verify they were in class the full time and to verify where they were last. If that student turns up missing, the school&#8217;s security system will know where they were last, and when.</p>
<p>These same ID cards can be used for faculty and staff. Maintenance crews can have access to boiler rooms or other mechanised areas, while students are not able to enter. Office staff can have access to private computer records, while the student staff is denied.</p>
<p>This level of security in any school system may seem worrying to some people, but in today&#8217;s world: it&#8217;s a reality that needs to be addressed. With so many people to keep track of these days, especially in today&#8217;s volatile society, security could be a nightmare but, can be easily managed. Therefore there is a strong need for ID cards especially among students to monitor and ensure a safe learning environment.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitychef.com/2011/student-id-necessary-for-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What Do You Need To Feel Secure?</title>
		<link>http://securitychef.com/2011/what-do-you-need-to-feel-secure/</link>
		<comments>http://securitychef.com/2011/what-do-you-need-to-feel-secure/#comments</comments>
		<pubDate>Fri, 29 Jul 2011 04:27:19 +0000</pubDate>
		<dc:creator>alice</dc:creator>
				<category><![CDATA[Personal Protection]]></category>

		<guid isPermaLink="false">http://securitychef.com/?p=279</guid>
		<description><![CDATA[One value that seems to hold a lot of people back from setting and achieving big goals is the need for security. Security is a feeling of certainty that everything is OK and that all your basic needs will be provided for. On the surface there’s nothing wrong with that. It’s great to feel secure. [...]]]></description>
			<content:encoded><![CDATA[<p>One value that seems to hold a lot of people back from setting and achieving big goals is the need for security. Security is a feeling of certainty that everything is OK and that all your basic needs will be provided for. On the surface there’s nothing wrong with that. It’s great to feel secure. Abraham Maslow lists it as one of the basic human needs. If we don’t feel secure, we can’t move onto higher levels like love and self-actualization. If we have doubts about paying the rent at the end of the month, how can we possibly go after our really big dreams? You gotta feel secure first, right?</p>
<p>So how is it that most self-made millionaires in America started broke or in debt? How is it that some people are able to start a new business while completely broke and with little or no income and with no guarantee of success? Do entrepreneurial risk takers simply have a lower need for security? If you read the biographies of very successful people, you see a common pattern again and again — from an external point of view, most of these people were not in a secure situation when they started going after their dreams. Sylvester Stallone was so broke he had to sell his dog in order to afford to keep shopping around his Rocky script (which no one would buy). Tony Robbins did his dishes in his bathtub because his tiny apartment had no kitchen. Brian Tracy was a day laborer. Og Mandino was a homeless drunk who wandered into libraries to stay warm. Babe Ruth started out in an orphanage. While some successful people start out with a lot of advantages, most don’t.</p>
<p>Meanwhile, how is it that others who seem to be in a far more financially secure situation are paralyzed from taking action? People who have some money in the bank, a nice home, and a steady paycheck still don’t feel secure. Meanwhile, others with far worse starting positions pass them by. Why?</p>
<p>The reason isn’t that some people need security more than others. I think everyone needs to feel secure. The difference, however, is that the entrepreneurial-minded define security internally while others define security externally.</p>
<p>For example, those who can’t seem to take action will typically define security as $X in the bank, a house that’s fully paid for, a stable high-paying job with benefits, a solid relationship with the boss, a car that runs well, etc. Security is all about the externals. If the externals are stable, this person feels secure. But when the externals are threatened, such as the possibility of getting laid off, then this person doesn’t feel secure. This person will spend a lot of time striving to get these external factors in order.</p>
<p>But the entrepreneurial action-takers define security internally. Security comes from trusting in yourself — in your ability to think and to take action. As long as you have the ability to think and take action, you’re secure. Given this mindset you could be homeless and still feel secure. Why? Because you still have the ability to think and act — your homelessness is only a temporary setback. It’s not a threat to your security. So even while you may be in a financially unstable situation, external circumstances don’t threaten your security. Your security is guaranteed. It cannot be turned off by external events.</p>
<p>Now when it comes time to take action, you can see why one group will be paralyzed, while the other group will speed ahead. According to Maslow’s hierarchy of human needs, security is a more basic need than self-actualization. This means that you won’t be able to fully set and achieve big goals if you don’t feel secure. Security has to come first.</p>
<p>So given that most people don’t start out with sufficient resources to satisfy the external definition of security, those that define their security this way won’t be able to take action to go after their dreams until all the external factors are met. They’ll be waiting and waiting until they have enough money to feel secure, and only after that happens will they be able to go after their dreams. Most of the time, this will never happen — the person will die before they satisfy all these external factors. On the other hand, if they do manage to acquire sufficient resources to pursue their dreams, and their security is again threatened (for example, they lose too much money), then it’s time to put the dreams on hold and re-establish external security. This is a hugely ineffective way to pursue your dreams. In most cases it just won’t work at all. You’ll spend your whole life pursuing security instead of self-actualizing. And sadly, this is what most people currently do.</p>
<p>Now consider the entrepreneurial group who defines security internally. All you need to feel secure is to think and to take action. You don’t need any specific set of external circumstances to feel secure. You’re already secure because you believe in yourself. So you can move straight on to self-actualization, and you can stay there. You can continue to work on your dreams without pause. There’s no need to stop and satisfy some external need for security.</p>
<p>Having an external locus of control is paralyzing. If you define security externally, you’ll always be victimized by factors outside your control. But an internal locus of control is empowering. If you define security internally, you’ll always have that need met, no matter what happens outside your control. And thus, you’ll always be able to take action on your dreams, no matter what happens.</p>
<p>So how do you move from one group to the other? It’s nothing more than a choice. Just as you may have chosen to define security externally, you can choose to do the opposite. You can choose to look externally for verification of who you are and what you’re capable of (this is what most people do). Or you can look internally instead.</p>
<p>Believing that you can handle anything that comes your way is a choice. You don’t have to earn it. You don’t have to acquire a quantity of external validation to somehow earn permission to work on your dreams. You don’t need permission. You don’t need the external world to say, “OK, you’ve finally met the basic security requirements. You now have authorization to work on your dreams, as long as you maintain your current level of external security.”</p>
<p>Yes, it really is that simple, as stupid as it may seem. There’s no physical law that says you have to meet some arbitrary external security requirements before you can go after your dreams. You can be starting broke and in debt with no stable income, and you can still spend the bulk of your time going after your dreams. People keep doing this over and over and succeeding.</p>
<p>If you define security internally (and you’re completely free to select this option), many obstacles that seemed to hold you back will just melt away. While you should pay attention to possibilities like running out of money, most people overemphasize these obstacles and become paralyzed by them.</p>
<p>Money is an important resource to be sure. But time is far more important. When you run out of time, then you’re really done. But what happens when you run out of money? Did you know that you can run out of money and just keep on going? Running out of money doesn’t mean you have to stop living, and it doesn’t mean you have to stop going after your dreams. You don’t automatically die when you run out of money. No referee will show up and haul you off the field. The game doesn’t suddenly end.</p>
<p>The typical self-made millionaire has been broke or nearly broke an average of 3.2 times before making their first million. There are consequences to going broke, and you may need to tighten your belt for a while, but that doesn’t mean you have to stop. Running out of money is largely an imaginary obstacle. For those who define security externally, running out of money is a huge personal threat, something to be avoided at all costs. But for those who define security internally, running out of money is just a temporary setback. Donald Trump experienced this setback, as did Walt Disney, Abraham Lincoln, and many others who went after their dreams with tenacity.</p>
<p>It doesn’t matter where you’re starting from… whether you’re an employee or an entrepreneur, whether you have a lot of cash or are broke and in debt. Time is so much more precious than money. You can afford to lose all your money in the pursuit of your dreams. You can go broke over and over and just keep on going. But what you cannot afford to lose is time. Money can be restored. Time cannot. Even if you have no money at all, you can still think and take action. But when you run out of time, that’s it — game over. Each day of your life that passes is another day gone, never to return again. If you are paralyzing yourself with an external definition of security, you’re squandering your life away. If you aren’t spending your precious time working on your dreams — today, right now — then you’re just counting the days until you die. That external security will never come. The external factors will never be just right. If you are waiting for external security, you’re waiting for death. And in the meantime, you’re forgetting to live.</p>
<p>So what are you waiting for? External security is an illusion. In the words of Helen Keller: “Security is mostly a superstition. It does not exist in nature, nor do the children of men as a whole experience it. Avoiding danger is no safer in the long run than outright exposure. Life is either a daring adventure, or nothing.” So which will it be for you? Have you chosen the daring adventure, or have you chosen the nothing?</p>
]]></content:encoded>
			<wfw:commentRss>http://securitychef.com/2011/what-do-you-need-to-feel-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How does an HID Access card work?</title>
		<link>http://securitychef.com/2011/how-does-an-hid-access-card-work/</link>
		<comments>http://securitychef.com/2011/how-does-an-hid-access-card-work/#comments</comments>
		<pubDate>Thu, 12 May 2011 23:35:50 +0000</pubDate>
		<dc:creator>alice</dc:creator>
				<category><![CDATA[ID Cards & Photo Badges]]></category>

		<guid isPermaLink="false">http://securitychef.com/?p=272</guid>
		<description><![CDATA[Are you looking for a card that allows door activation or can login to a networked computer? You&#8217;ll need a card with embedded information encoded inside, this is known as an HID proximity card. With an access card system like this, reports can be generated to provide specific details as to which card holders have [...]]]></description>
			<content:encoded><![CDATA[<p>Are you looking for a card that allows door activation or can login to a networked computer? You&#8217;ll need a card with embedded information encoded inside, this is known as an HID proximity card. With an access card system like this, reports can be generated to provide specific details as to which card holders have attempted access and which cards have activated entry.</p>
<p>An HID proximity card has the capability within an access system to activate a door or log someone into a computer network. The card does not however have the capability of accessing an area within itself. The card within the framework of an access system will provide security and appropriate access to a controlled area.</p>
<p>This complete access system is able to function as a security officer that allows card holders into specific secured doors at certain dates and times. This is because the card is combined with a card reader, access control panel and a computer. </p>
<p>To identify a card holder, the card holds an embedded binary code, which is a sequence of ones and zeros where a specific sequence is used. The coding format is transmitted from the card reader to the control panel for deciphering. The card may or may not have additional code embedded in the card. The access control panel normally does not use extra coding, but reviews the formatted code utilized in the system.</p>
<p>When the data is received by the controller, it begins the steps of verifying if the cardholder has access to the building. The length of the data string is analyzed prior to proceeding. If the format is different, the control panel will not be able to process the request. Once the format is verified, the controller can then check the facility code and site code for a match. If this is true, the controller moves ahead to match the card number. A matching card number will move the analysis forward. The information is then reviewed to see if the card holder has authorization to access during the date and time the access request is made. If so, the lock relay will activate and the door or network will unlock for access.</p>
<p>Access is denied if the HID proximity card is not able to successfully move through the above steps. The system may provide a specific response from the controller or there may not be any response at all.</p>
<p>The software application processing authentication transactions can be accessed by authorized personnel to updated cardholder information, configure hardware and to generate reports of access attempts and successes.</p>
<p>for more information: <a href="http://news.safecardid.com/2011/hid-access-cards-how-they-work">http://news.safecardid.com/2011/hid-access-cards-how-they-work</a>?</p>
]]></content:encoded>
			<wfw:commentRss>http://securitychef.com/2011/how-does-an-hid-access-card-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Is a Low Priority for Cloud Service Vendors, Study Finds</title>
		<link>http://securitychef.com/2011/security-is-a-low-priority-for-cloud-service-vendors-study-finds/</link>
		<comments>http://securitychef.com/2011/security-is-a-low-priority-for-cloud-service-vendors-study-finds/#comments</comments>
		<pubDate>Wed, 04 May 2011 21:47:52 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://securitychef.com/?p=265</guid>
		<description><![CDATA[Security is a relatively low priority for many cloud service providers, according to Security of Cloud Computing Providers, a new study conducted by the Ponemon Institute. Cloud providers and customers also have widely differing views on who’s most responsible for securing sensitive data, the study found. Less than 30 percent of the 127 U.S. and [...]]]></description>
			<content:encoded><![CDATA[<p>Security is a relatively low priority for many cloud service providers, according to Security of Cloud Computing Providers, a new study conducted by the Ponemon Institute. Cloud providers and customers also have widely differing views on who’s most responsible for securing sensitive data, the study found.</p>
<p>Less than 30 percent of the 127 U.S. and European vendors surveyed said they considered security one of their “most important responsibilities,” according to the study. In addition, 62 percent of U.S. respondents and 63 percent of European respondents said they were either not confident or not sure that their services adequately protected customer information.</p>
<p>Such findings are surprising, given the well-publicized risks associated with the loss of sensitive data, according to a blog post by Dr. Larry Ponemon, the Institute’s president.</p>
<p>&nbsp;</p>
<p>Many cloud vendors also don’t believe security is an important factor in how customers choose providers. Just 19 percent of American and 18 percent of European respondents said they considered security to be a competitive advantage. The top reasons customers migrate to a cloud environment include cost reduction, faster deployment time, and improved customer service, according to respondents.</p>
<p>Vendors and users also appear to have different perspectives on who should be most responsible for security in the cloud. Sixty-nine percent of providers believe customers are mainly responsible for security; in contrast, 35 percent of cloud users consider themselves responsible for security, according to an earlier Ponemon study. In addition, just 16 percent of cloud providers, compared to 33 percent of customers, believe security should be a shared responsibility.</p>
<p>Given the risks associated with losing sensitive data, however, “it is only a matter of time” before organizations will “demand enhanced security systems,” according to Dr. Ponemon&#8217;s statement.</p>
<p>In the meantime, cloud customers should be aware of their responsibility to asses security risks before placing data in the cloud, he said. They must thoroughly &#8220;vet providers and their applications and infrastructure for their ability to safeguard information.” More cloud services providers and customers should also consider sharing responsibility for security, he said.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitychef.com/2011/security-is-a-low-priority-for-cloud-service-vendors-study-finds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Service Away From Home</title>
		<link>http://securitychef.com/2011/internet-service-away-from-home/</link>
		<comments>http://securitychef.com/2011/internet-service-away-from-home/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 02:42:28 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Personal Protection]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://securitychef.com/?p=249</guid>
		<description><![CDATA[There are three things you need to consider when using an internet service away from home: your internet provider, your internet connection, and your computer. Your ISP can monitor everything you do. I&#8217;m not saying that they are, but they can. Whenever you&#8217;re using a wireless hotspot such as in an internet cafe, or even [...]]]></description>
			<content:encoded><![CDATA[<p>There are three things you need to consider when using an internet service away from home: your internet provider, your internet connection, and your computer. Your ISP can monitor everything you do. I&#8217;m not saying that they are, but they can.</p>
<p>Whenever you&#8217;re using a wireless hotspot such as in an internet cafe, or even a wired connection in a hotel or somewhere else, they are your ISP for that connection. Again, I&#8217;m not saying that the coffee shop, hotel or their wireless provider is spying on you, but I would take care to make sure you trust the provider you&#8217;re using. If you&#8217;re at &#8220;Joe&#8217;s Cafe&#8221; and it&#8217;s Joe&#8217;s teenage son that&#8217;s just slapped a wireless access point on their DSL connection &#8211; yes, he could certainly be monitoring what you&#8217;re up to if you&#8217;re not careful.</p>
<p>But that&#8217;s not really the biggest threat. So while you should of course exercise caution, for this discussion I&#8217;ll simply assume we can trust whoever&#8217;s providing the internet connectivity. &#8220;Anyone within wireless range of your laptop could be monitoring your internet usage.&#8221;The people we shouldn&#8217;t trust are the other users within range of that wireless connection.Anyone within wireless range of your laptop could be monitoring your internet usage.</p>
<p> Scary, huh?</p>
<p> So, here&#8217;s what you need to do:</p>
<p>•Use a firewall! Sounds like you&#8217;re already doing this, but for everyone else, this is critical. And it doesn&#8217;t have to be difficult; for example, I simply enable the built-in Windows firewall when I&#8217;m in an open WiFi situation.</p>
<p>Yes, there may be a router or firewall at the hotspot protecting you from threats from the internet, and that&#8217;s fantastic. It&#8217;s also not at all what I&#8217;m talking about here. In an open WiFi situation and in any &#8220;internet provided&#8221; situations like hotels, you need to protect yourself from everyone else that&#8217;s on the same side of the router as you are. They can see and connect directly to your machine unless you have enabled your firewall.</p>
<p>•Use httpS! That&#8217;s https; note the &#8220;s&#8221; at the end. An https connection is encrypted. That means that while someone can see that you&#8217;re accessing a particular web site, if you&#8217;re using https they cannot see any of the data you send to or receive from that site. This is the only safe way to do online banking. If you can&#8217;t connect via https, or the &#8220;s&#8221; disappears at some point in your exchange with your bank, then stop immediately. If it&#8217;s not https it&#8217;s not secure and anyone in the room could be monitoring what you&#8217;re doing.</p>
<p>•Secure your Email! Email is perhaps the biggest open security hole in these situations. If you use a POP3/SMTP email client, the default configuration for most is totally unsecure. I could sit in a corner of the internet cafe and not only read your email with you, but also steal your account name and password. It really is that unsecure.</p>
<p>With POP3 and SMTP you should contact your email provider and see if they support SSL connections. If they do, it&#8217;s a slightly different configuration in your email program but once done all of the communication between your email program and email servers are securely encrypted.</p>
<p>Online or web-based email services deserve special consideration. Most do not support https connections. The one exception is Gmail, which will use https if you make sure to login through an https connection, and have the &#8220;always use https&#8221; option selection in Gmail&#8217;s options.</p>
<p>•Consider a VPN. Not all sites support https as it takes extra work on their part. For example, there is no https version of ask-leo.com; you can only access it through unencrypted http, and that&#8217;s the norm for most sites that don&#8217;t process confidential information. But that means that someone could still be watching where you go. If you don&#8217;t mind them seeing that you&#8217;re visiting ask-leo.com, or what you might happen to search for on Google, or whatever other sites you&#8217;re visiting in the clear, then you don&#8217;t need to do anything.</p>
<p> And not all email providers will provide secure connections.</p>
<p>However, if you&#8217;re a &#8220;road warrior&#8221; and spend a lot of time in internet cafes, have an unsecure email configuration, or browse a lot of sites that you&#8217;d rather not be so easily sniffable, you might consider a VPN (Virtual Private Network) service. I&#8217;ve never used one personally, so I can&#8217;t recommend one specifically, but there are several. http://www.hotspotvpn.com/ is one example. Using these services you create an encrypted connection to the service and route all your internet traffic through them. When you do this, the folks in the cafe see only encrypted data which they can do nothing with.</p>
<p>•Realize that a &#8220;login intercept&#8221; protects them, not you. In many free WiFi situations the first time you use the service no matter where you try to go you&#8217;re first intercepted and sent to a page where you&#8217;re required to &#8220;login&#8221; or otherwise accept the terms of service. This page does not protect you at all. It has nothing to do with security, wireless or otherwise. It&#8217;s nothing more than a bit of legalese to protect the internet provider.</p>
<p>So, how big is the risk, really? It depends.I would expect busy hotspots near sensitive areas to be a fairly reasonable risk. Busy coffee houses, open airport WiFi, libraries and the like seem like &#8220;target rich environments&#8221; for the potential hacker. These are certainly places where I&#8217;d make sure to take these safety measures myself. Less busy hotspots? Perhaps not so much. But it is possible, and more frighteningly, it&#8217;s not all that hard for someone who&#8217;s technically savvy.</p>
<p> Article C3269 &#8211; November 12, 2009</p>
]]></content:encoded>
			<wfw:commentRss>http://securitychef.com/2011/internet-service-away-from-home/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Danger in Internet Hot Spots</title>
		<link>http://securitychef.com/2011/danger-in-internet-hot-spots/</link>
		<comments>http://securitychef.com/2011/danger-in-internet-hot-spots/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 02:22:47 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Personal Protection]]></category>

		<guid isPermaLink="false">http://securitychef.com/?p=239</guid>
		<description><![CDATA[There&#8217;s a potential threat lurking in your internet café, say University of Calgary computer science researchers. It&#8217;s called Typhoid adware and works in similar fashion to Typhoid Mary, the first identified healthy carrier of typhoid fever who spread the disease to dozens of people in the New York area in the early 1900s. &#8220;Our research [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s a potential threat lurking in your internet café, say University of Calgary computer science researchers. It&#8217;s called Typhoid adware and works in similar fashion to Typhoid Mary, the first identified healthy carrier of typhoid fever who spread the disease to dozens of people in the New York area in the early 1900s.</p>
<p>&#8220;Our research describes a potential computer security threat and offers some solutions,&#8221; says associate professor John Aycock, who co-authored a paper with assistant professor Mea Wang and students Daniel Medeiros Nunes de Castro and Eric Lin. &#8220;We&#8217;re looking at a different variant of adware &#8212; Typhoid adware -which we haven&#8217;t seen out there yet, but we believe could be a threat soon.&#8221;</p>
<p>Adware is software that sneaks onto computers often when users download things, for example fancy tool bars or free screen savers, and it typically pops up lots and lots of ads. Typhoid adware needs a wireless internet café or other area where users share a non-encrypted wireless connection.</p>
<p>&#8220;Typhoid adware is designed for public places where people bring their laptops,&#8221; says Aycock. &#8220;It&#8217;s far more covert, displaying advertisements on computers that don&#8217;t have the adware installed, not the ones that do.&#8221;</p>
<p>The paper demonstrates how Typhoid adware works as well as presents solutions on how to defend against such attacks. De Castro recently presented it at the EICAR conference in Paris, a conference devoted to IT security.</p>
<p>Typically, adware authors install their software on as many machines as possible. But Typhoid adware comes from another person&#8217;s computer and convinces other laptops to communicate with it and not the legitimate access point. Then the Typhoid adware automatically inserts advertisements in videos and web pages on the other computers. Meanwhile, the carrier sips her latté in peace &#8212; she sees no advertisements and doesn&#8217;t know she is infected ¬- just like symptomless Typhoid Mary.</p>
<p>U of C researchers have come up with a number of defenses against Typhoid adware. One is protecting the content of videos to ensure that what users see comes from the original source. Another is a way to &#8220;tell&#8221; laptops they are at an Internet café to make them more suspicious of contact from other computers.</p>
<p>&#8220;When you go to an Internet café, you tell your computer you are there and it can put up these defenses. Anti-virus companies can do the same thing through software that stops your computer from being misled and re-directed to someone else,&#8221; says Aycock.</p>
<p>Why worry about ads? Aycock explains it this way: &#8220;Not only are ads annoying but they can also advertise rogue antivirus software that&#8217;s harmful to your computer, so ads are in some sense the tip of the iceberg.&#8221;</p>
<p>The paper Typhoid Adware can be found: <a href="http://pages.cpsc.ucalgary.ca/~aycock/papers/eicar10.pdf">http://pages.cpsc.ucalgary.ca/~aycock/papers/eicar10.pdf</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitychef.com/2011/danger-in-internet-hot-spots/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wireless Hot Spot Security</title>
		<link>http://securitychef.com/2011/wireless-hot-spot-security/</link>
		<comments>http://securitychef.com/2011/wireless-hot-spot-security/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 02:22:22 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Personal Protection]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://securitychef.com/?p=236</guid>
		<description><![CDATA[Hot spots are hot. Located in thousands of airport lounges, hotels, cafés, and even public parks, they allow anyone with an 802.11b wireless LAN card to surf the Web, check e-mail, or even connect to the company LAN at broadband speeds. Before you experience the thrill of surfing the Net while nursing a latte at [...]]]></description>
			<content:encoded><![CDATA[<p>Hot spots are hot. Located in thousands of airport lounges, hotels, cafés, and even public parks, they allow anyone with an 802.11b wireless LAN card to surf the Web, check e-mail, or even connect to the company LAN at broadband speeds. Before you experience the thrill of surfing the Net while nursing a latte at Starbucks, however, be sure you take the necessary precautions.</p>
<p>All wireless LANs have security issues, but wireless hot spots raise unique concerns. As with any wireless LAN, signals can penetrate walls and ceilings. That means that anyone in range with a standard wireless card can connect, even if they&#8217;re sitting out in the parking lot.</p>
<p>Hot-spot services are designed for maximum ease of use, so they generally don&#8217;t offer WEP or WPA encryption; if you connect to a hot spot, just about all the data you send is probably unencrypted. Since wireless LANs allow peer-to-peer connections, the computer-savvy guy at the corner table may be able to connect to your notebook and mooch your Internet connection, look at your unprotected files, or hitch a ride as you connect to your corporate LAN. He can also eavesdrop the airwaves with one of the many wireless sniffers available on the Web and watch as you unintentionally reveal your corporate network log-on information, your credit card numbers, IP addresses of your connections, and even the contents of e-mails, instant messages, and file attachments. Anyone with malicious intent can do lots of damage with this information, both to you and the company that employs you. And of course, you&#8217;re vulnerable to the same viruses, worms, and other attacks as you would be on any unprotected network.</p>
<p>So what can you do? Here are several ways you can protect yourself.</p>
<p>• Disable your wireless card&#8217;s ad-hoc (peer-to-peer) mode. You can do this via the adapter&#8217;s utilities or within Windows XP by clicking on Network Connections in the Control Panel. This will help prevent anyone from connecting to your notebook.</p>
<p>• Remove or disable your wireless card if you&#8217;re working offline.</p>
<p>• Install a personal firewall. Windows XP offers the rudimentary Internet Connections Firewall, but more advanced personal firewall products, such as Symantec&#8217;s Norton Internet Security and Zone Labs&#8217; ZoneAlarm, can prevent others from accessing your notebook and even alert you when an attempt is made.</p>
<p>• Install personal antivirus software from McAfee, Symantec, or another antivirus vendor, and enable automatic signature updates.</p>
<p>• Take advantage of your e-mail client&#8217;s security features, particularly digital signatures and e-mail encryption. Digital signatures verify your identity to your recipients and ensure that messages are not tampered with during transmission. Microsoft Outlook lets you add digital signatures to messages and encrypt messages and attachments using S/MIME. If you&#8217;re using a Web-based e-mail service, make sure it offers some type of encryption. Be aware, however, that in many cases with such services only the log-on information is encrypted, while text is sent in the clear. You may want to use third-party e-mail encryption utilities, such as PGP Corp.&#8217;s PGP Personal, which offers digital signatures and strong encryption for messages and attachments, as well as for files stored on your computer.</p>
<p>• Make sure you submit credit card information only to SSL-protected Web sites (look for https:// in the address bar).</p>
<p>• For the best protection, use a virtual private network (VPN) to provide strong authentication and encryption for all your hot-spot communications. This is particularly important if you&#8217;re connecting to your company&#8217;s network, in which case you&#8217;ll probably get VPN client software from your IT manager. Small-business users can install VPN-enabled firewall and router appliances from Netgear, SonicWall, 3Com, or Watchguard at the office or use one of the many small-business VPN services available, for example, from Sprint or Verio. • Keep your OS and software up to date with security patches.</p>
<p>And of course, make sure nobody is looking over your shoulder as you enter vital information. Enjoy the freedom and convenience that hot spots offer, but make sure that hot spots don&#8217;t land you in hot water.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitychef.com/2011/wireless-hot-spot-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is your online shopping experience safe?</title>
		<link>http://securitychef.com/2011/is-your-online-shopping-experience-safe/</link>
		<comments>http://securitychef.com/2011/is-your-online-shopping-experience-safe/#comments</comments>
		<pubDate>Tue, 26 Apr 2011 02:06:29 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Personal Protection]]></category>

		<guid isPermaLink="false">http://securitychef.com/?p=231</guid>
		<description><![CDATA[Before you click and buy, make sure your online shopping experience is a safe and enjoyable one. Who are you dealing with? Check the identity of the retailer, especially if you&#8217;ve never heard of them before. Only buy from sites that include adequate address and contact details &#8211; phone, fax, email, and street address (not [...]]]></description>
			<content:encoded><![CDATA[<p>Before you click and buy, make sure your online shopping experience is a safe and enjoyable one.</p>
<p>Who are you dealing with?<br />
Check the identity of the retailer, especially if you&#8217;ve never heard of them before. Only buy from sites that include adequate address and contact details &#8211; phone, fax, email, and street address (not just a PO Box number).<br />
Find out how easy they are to contact. Look for links such as &#8220;Contact us&#8221; or &#8220;Help&#8221;. It may be worth calling the phone number to see if someone answers, or sending an email to see how quickly you get a response.<br />
If you&#8217;re still unsure about a retailer&#8217;s track record, do some research online. Search for complaints by typing their name plus &#8220;complaint&#8221; or &#8220;problem&#8221; into Google&#8217;s forums. You can also check whether the trader has met the standards of companies that rate online sellers (such as <a href="http://www.shopsafe.co.nz/">www.shopsafe.co.nz</a>, <a href="http://www.bizrate.com/">www.bizrate.com</a> or <a href="http://www.bbbonline.com/">www.bbbonline.com</a> ).<br />
Be wary if you&#8217;re buying from a country where you don&#8217;t speak the language. Even if the website is in English it may be difficult to sort out a problem.<br />
Check out returns, refunds and warranties<br />
When you buy online, there&#8217;s a greater chance the product won&#8217;t be quite what you wanted &#8211; clothes might not fit, or an appliance may not measure up to its claims. Check that there&#8217;s a clear returns policy offering a full refund if goods are faulty or not what you ordered.<br />
For appliances and electrical goods, check if the warranty is valid in New Zealand &#8211; you may need to ask for an international warranty instead. Also check that the company has a New Zealand agent who can repair the item if anything goes wrong. Local agents are usually under no obligation to repair goods they haven&#8217;t sold.<br />
Before you place the order, find out when and how you could cancel it or return something for a refund. Are there restrictions on returns? For example, CDs, DVDs and cosmetics must be returned in unopened packaging.<br />
An item may have a money-back-guarantee &#8211; but if you&#8217;re returning it because you&#8217;ve changed your mind, expect to pay the (often expensive) return postage. Where goods are faulty or if you&#8217;re sent the wrong item, you should be able to claim the postage costs back from the retailer. This may take some perseverance, however.<br />
Safeguard your personal details<br />
Check the site&#8217;s privacy policy and be wary if there isn&#8217;t one. A clear privacy policy describes the type of personal information collected from a customer, the reason the information is collected, and who will have access to it.<br />
You should be able to opt out of being placed on any third-party lists. The &#8220;better&#8221; sites don&#8217;t share information with third parties unless you give explicit consent.<br />
Check where your details will be stored later &#8211; some businesses store them on a secure server, others destroy them once the transaction is made.<br />
Work out the cost<br />
What&#8217;s the exchange rate? Some sites have currency calculators to help you work this out. But when they don&#8217;t, it&#8217;s easy to forget you&#8217;re dealing in US dollars or UK pounds &#8211; and you may get an unexpected surprise when your credit card statement arrives.<br />
Check the total costs carefully to make sure they include delivery, taxes, and any other costs. These costs should be disclosed before you start ordering &#8211; and certainly before you finalise your order.<br />
Sites should offer both &#8220;regular&#8221; and &#8220;express&#8221; delivery options. If the retailer can&#8217;t give you a specific delivery cost, make sure you know the maximum amount you&#8217;ll have to pay. The cost of postage and packing can greatly increase the price if you&#8217;re buying from overseas &#8211; so it might pay to buy several items, to make the postage worthwhile. If you need the goods by a certain date, make this clear to the retailer.<br />
Keep your credit card details safe<br />
Check out the site&#8217;s security policy. In particular, make sure that the site has a secure checkout. This means your personal information is &#8220;scrambled&#8221; as it travels over the web and others can&#8217;t tap into your details.<br />
A secure page will have one or more of the following:<br />
* a pop-up window warning that you&#8217;re about to enter a secure site<br />
* an unbroken key icon<br />
* a URL (website address) that begins with &#8220;https&#8221; instead of the usual &#8220;http&#8221;<br />
* a closed padlock icon &#8211; padlock icons can be faked so look for one other secure page indicator.<br />
If the site doesn&#8217;t have a secure checkout, then never email credit card details to a merchant &#8211; use the phone, fax, or snail mail. These methods are more secure.<br />
Paying by credit card can give you extra protection if things go wrong, because you have the right to pursue a claim with the card issuer as well as the internet retailer.<br />
Some sites offer &#8220;Verified by Visa&#8221; or MasterCard&#8217;s &#8220;SecureCode&#8221;. These verify your identity before processing transactions &#8211; you&#8217;ll be asked for a user name and password as well as your credit card details. This provides another level of security.<br />
Be aware of the limitations of secure websites. The security icons tell you your details are protected during transit. But once your details arrive at the retailer&#8217;s site there could be a risk that they&#8217;re not stored properly. To get around this risk, some retailers use a third party such as WorldPay or PayPal. You need to register with this third party &#8211; but it means you don&#8217;t need to give your details to people you transact with. Large sites like Amazon, eBay, and Strawberry Net offer this service.<br />
TIP! Some of our readers told us that, for online orders, they use a separate credit card with a lower limit &#8211; it lowers the risk of online shopping.<br />
Set up a paper trail<br />
Always keep a paper trail. Print off and keep a copy of your order and any confirmation or receipt that you get. It&#8217;s also a good idea to keep a copy of the terms and conditions at the time of purchase.<br />
Check whether you&#8217;ve been charged correctly and make sure your order matches your bill.<br />
If you contact the retailer at any time because your goods didn&#8217;t turn up or are faulty, make a note of it.<br />
What if things go wrong?<br />
Make sure the site has a complaints procedure, and that it gives contact details for handling complaints.<br />
If you buy goods from a New Zealand trader you&#8217;re covered by the Consumer Guarantees Act (CGA).<br />
If you believe a New Zealand trader has breached the CGA, you can go to the Disputes Tribunal.<br />
If you&#8217;re buying from an overseas site, check which law applies to the contract you&#8217;re entering into. In theory, you should have the protection of the relevant country&#8217;s consumer laws, but it could be difficult to sort things out if something goes wrong.<br />
Had a problem with an overseas internet trader? Visit <a href="http://www.econsumer.gov/">www.econsumer.gov</a>. This website (a venture of the International Consumer Protection and Enforcement Network) contains contact details for some overseas consumer agencies, advice and guidance on resolving an online shopping complaint, and gives you the opportunity to file a complaint.<br />
The New Zealand Marketing Association can also help in settling disputes &#8211; it may work with a direct marketing association in that company&#8217;s home country.<br />
If you don&#8217;t get the goods you ordered, or if they&#8217;re of an unacceptable quality, ask your bank for a &#8220;chargeback&#8221;. Banks may be willing to cancel the transaction and reverse the payment to the trader. Policies vary, so check with your bank. There may be a time limit on complaints, so contact your bank as soon as you&#8217;re aware of the problem.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitychef.com/2011/is-your-online-shopping-experience-safe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Credit card secuiry online</title>
		<link>http://securitychef.com/2011/credit-card-secuiry-online/</link>
		<comments>http://securitychef.com/2011/credit-card-secuiry-online/#comments</comments>
		<pubDate>Tue, 26 Apr 2011 02:04:26 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Personal Protection]]></category>

		<guid isPermaLink="false">http://securitychef.com/?p=229</guid>
		<description><![CDATA[Online shopping is pretty common in the 21st century, many people have bought something online in one form or another. There are some great bargains online to be had, as many online stores offer discounts that make you wonder why anyone still goes to retails stores. Some shoppers, however, are still hesitant about shopping online. We&#8217;ve [...]]]></description>
			<content:encoded><![CDATA[<p>Online shopping is pretty common in the 21st century, many people have bought something online in one form or another. There are some great bargains online to be had, as many online stores offer discounts that make you wonder why anyone still goes to retails stores.</p>
<p>Some shoppers, however, are still hesitant about shopping online. We&#8217;ve all heard some of the stories of people getting ripped off by illegitimate web stores &#8211; and there is reason to be cautious online, as there are some very unreliable &#8216;online stores&#8217; out there. Shopping on the net doesn&#8217;t have to make you weary, as there are many ways to ensure safe shopping online for you and your family.</p>
<p>The risks of online bargain shopping can be minimised by first only buying from reputable sources. As a general rule, the bigger and more well known the website, the better. Generally, the only problems that will occur with large online stores are delays or mispacking, very rarely do goods go missing or never turn up when you buy online from a well-known company. Because large companies also have service teams who deal with orders all day long, they will be able to sort out any issues that do arise for you at their cost.</p>
<p>Problems more often arise when shopping online when a shopper wants a particular product with limited availability &#8211; whereby they need to go to a lesser known online store to purchase the product, or purchase the products from the other side of the world. While there are many large international online retailers which are safe to deal with (Amazon, for example), use your instincts when thinking about making a purchase from a website which looks low in quality and that you&#8217;ve never heard of before. Finding details such as a physical address and phone number is often a good sign if you are unsure, so don&#8217;t hesitate to call and make sure there is someone on the other line to take your call.</p>
<p>Finding Secure Websites<br />
The first step in safe online shopping is making sure the website you are about to buy from is secure. Once you&#8217;re at the online checkout, make sure you can see a small, locked padlock in the bottom right-hand corner of your internet browser. Be careful to make sure that the padlock is actually on the browser itself, as there are many websites which simply mimic that padlock with an image on their web page, leading shoppers to believe they are buying securely. Additionally, make sure the URL starts with https:// (the &#8216;s&#8217; stands for secure).</p>
<p>Double clicking on this padlock to view the page owner information will ensure its validity &#8211; but remember you also need to check the security certificate within the Page Info pop-up to make sure it is current, and has not expired. You will also want to check the company who are listed as issuing the certificate, to make sure they are a trusted third party. This should be a well known third party such as VeriSign, Secure SSL, Thawte or USERTRUST &#8211; but if you are unsure, just do an online search for information about them and visit their website as a background check.</p>
<p>Paying By Credit Card<br />
Once you&#8217;ve determined that the website you are buying from is reputable and that their security certificate is valid, you can proceed with payment.</p>
<p>When checking the certificate details, you will have noticed the technical details of the encryption &#8211; all reputable online stores will be using 128 or 256 bit high grade encryption. This kind of encryption makes it extremely difficult for unauthorised people to view any information travelling via the internet from your computer to the online store&#8217;s database.</p>
<p>As an alternative to credit cards, many websites offer the use of PayPal, which is a trusted third party which holds your money from an electronic transfer until the sale in completed, rather than the money going straight to the online store. This is a great option to use where available.</p>
<p>Assuming you&#8217;ve followed the above precautions, you can feel very safe with entering your credit card details online, along with your shipping details. For new online shoppers, it may take a few purchases to make you feel comfortable with paying online &#8211; but sticking with reliable suppliers should ensure you a seamless process every time.</p>
<p>Make Sure You Log Out!<br />
Even if you&#8217;re using you home computer (but more importantly, if you&#8217;re using a work, public or someone else&#8217;s computer), make sure you log out of the online store&#8217;s database. While most reputable stores have time-out precautions for log-ins, it&#8217;s best to never risk having your personal payment details openly stored in your browser. As an additional precaution, you can clear the history, cookies, cache and other private data from the Options menu in your web browser, to ensure nothing is stores for anyone else to stumble upon.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitychef.com/2011/credit-card-secuiry-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security advice for secure shopping online</title>
		<link>http://securitychef.com/2011/security-advice-for-secure-shopping-online/</link>
		<comments>http://securitychef.com/2011/security-advice-for-secure-shopping-online/#comments</comments>
		<pubDate>Tue, 26 Apr 2011 02:02:27 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Personal Protection]]></category>

		<guid isPermaLink="false">http://securitychef.com/?p=227</guid>
		<description><![CDATA[Well how concerned are we about the use of our credit cards for secure shopping online?  In the modern world where e-commerce, m-commerce, e-tailing or e-retailing continues to increase in volume and value at an exponential rate most/all e-tail businesses have recognised the importance of online security. These e-tailers have realised if they do not [...]]]></description>
			<content:encoded><![CDATA[<p>Well how concerned are we about the use of our credit cards for secure shopping online?</p>
<p> In the modern world where e-commerce, m-commerce, e-tailing or e-retailing continues to increase in volume and value at an exponential rate most/all e-tail businesses have recognised the importance of online security. These e-tailers have realised if they do not protect their customer by ensuring a safe transaction they would lose their business.</p>
<p> As online security has been an age old problem most developers of software have given this issue much thought and have incorporated security features in their software, this would apply to most new browsers, e-mail systems and operating systems. Many e-tailers make use of data encryption once we have entered the checkout area. It is often believed using your credit card for online shopping with a secure trader is as safe as giving your credit card to a waiter at a restaurant or coffee shop.</p>
<p> It is also strongly recommended that any online shopping is done from a computer or device which is personal and which is NOT located in a public area and accessed by all and sundry. Computers located in the public areas can be susceptible to being fitted with scanner devices by fraudsters.</p>
<p> So how can we tell that the e-tail shop has a secure checking out system?</p>
<p> As an online shopper from home, once you have selected your desired item placed it in your shopping cart or basket and proceed to check out the following changes will be noted when trading across a secure link.</p>
<p> •The http:// will change to https:// where the s denotes the secure link</p>
<p> •Also watch out for a padlock, where a symbol of a locked padlock would signal a secure link, which may appear in the navigation bar or on the bottom right hand side of the screen</p>
<p> •Ensure that we are familiar with the privacy policy as published by the seller to ensure they do not pass on any of our information to a third party and if they do under what circumstances</p>
<p> Please remember that it is still important to carry out the usual checks to verify the contactable details of the online shopping mall store you are shopping at and all other usual credit card handling requirements apply</p>
]]></content:encoded>
			<wfw:commentRss>http://securitychef.com/2011/security-advice-for-secure-shopping-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

